PT-2003-1258 · Sun · Sun One Starter Kit

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2002-1525

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun ONE Starter Kit version 2.0
Description A directory traversal issue exists in the ASTAware SearchDisk engine, allowing remote attackers to read arbitrary files. This can be achieved through a .. (dot dot) attack on ports 6015 or 6016, or by using an absolute pathname to access port 6017.
Recommendations For Sun ONE Starter Kit version 2.0, restrict access to ports 6015, 6016, and 6017 to minimize the risk of exploitation. As a temporary workaround, consider disabling the ASTAware SearchDisk engine until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1525

Affected Products

Sun One Starter Kit